
PIPEDA Compliance: What Canadian Businesses Actually Have to Do
Ten principles, a breach register almost nobody keeps, and the question of whether PIPEDA even applies to you. A practical read of the federal privacy law.
GuardsArm Team
Security Experts

Most Canadian organisations treat PIPEDA as a privacy policy on the website and leave it there. The policy is the smallest part of it. The parts that generate findings are the accountability structure behind the policy, the breach register nobody is keeping, and a scope question many organisations answer wrongly in their own favour.
First: does it apply to you?
PIPEDA governs personal information collected, used or disclosed in the course of commercial activity. Three provinces — Quebec, British Columbia and Alberta — have private-sector laws declared substantially similar, so within those provinces their law generally governs local commercial activity instead.
That exemption is narrower than people assume. PIPEDA still reaches you if:
| Situation | PIPEDA applies |
|---|---|
| Federally regulated business (bank, telecom, airline, inter-provincial transport) | Yes, wherever you operate |
| Personal information crossing a provincial border in commercial activity | Yes |
| Personal information crossing the national border | Yes |
| Employee data, federally regulated employer | Yes |
| Employee data, provincially regulated employer | No — provincial law, or nothing |
A BC company with customers in Ontario is not in a single-regime world. See operating across provinces.
The ten principles, grouped by what they cost you
Schedule 1 lists ten fair information principles. They are not equally demanding in practice.
Accountability is the one with teeth. You must designate an individual responsible for compliance, and that person's name has to be available on request. In smaller organisations this is often assigned and then never resourced — which is exactly what an investigation surfaces.
Limiting collection, use and retention is where most organisations are quietly offside. Data collected for one purpose gets reused for another, and retention schedules either do not exist or are not enforced by anything technical.
Safeguards is the principle a security assessment maps to directly, and the only one where the wording explicitly scales protection to the sensitivity of the information.
The breach obligations, in the order they bite
Since November 2018 breach reporting has been mandatory. There are three distinct duties and organisations routinely satisfy only the first two.
The threshold for reporting and notifying is a real risk of significant harm — assessed on the sensitivity of the information and the probability of misuse. Significant harm is broadly drawn: humiliation, damage to reputation or relationships, identity theft, financial loss, loss of employment or professional opportunity.
That register is the cheapest compliance win available. It is a spreadsheet with a row per incident, and its absence is an offence in itself.
What to fix first
Ranked by how often it is missing and how quickly it can be closed:
- Name the accountable individual and give them a budget line
- Start the breach register today, backdated as far as your records allow
- Write down a retention schedule and enforce at least one part of it technically
- Map where personal information crosses a border — provincial or national
- Run a risk assessment against the safeguards principle, not against a generic checklist
Transfers to a processor are not disclosures requiring fresh consent, but accountability travels with the data: you remain answerable for what your processor does, and contractual protection comparable to your own is the mechanism. That makes vendor risk assessment a PIPEDA obligation rather than a nice-to-have.
What an OPC investigation actually asks for
The Commissioner operates an ombudsman model: findings and recommendations rather than fines. That shapes what an investigation feels like. Rather than calculating a penalty, the office establishes what happened and whether your practices meet the principles, then publishes a finding.
What gets requested, near-universally:
- The name and role of your accountable individual, and evidence they were actually exercising the function
- Your retention schedule, and evidence it was applied to the data in question
- The risk assessment behind your safeguards — not a statement that they were reasonable, but the reasoning
- Your breach register, in full
- Contracts with any processor involved, showing comparable protection
Organisations that struggle are rarely the ones with weak technology. They are the ones that made sound decisions without recording why, and cannot reconstruct the reasoning a year later.
GuardsArm runs PIPEDA gap assessments and builds the accountability and breach machinery behind them. See PIPEDA compliance services or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


